
Written By
Andy Dowling
How to approach insider threats with ISO 27001.
It wasn't a call we get every day.
A client that held highly valuable intellectual property at the core of their business had recently sourced a specialist network-connected device - from a supplier in a country known for aggressive industrial espionage.
Their question: Could this device be used as a backdoor?
They weren’t being paranoid. They knew the value of their IP, and they knew who might want it.
We worked closely with them to assess the risk. Together, we implemented technical controls to isolate the device and restrict its access to sensitive systems.
But then, the situation escalated.
Not long after the controls were put in place, an employee reported being approached by representatives of the same supplier. Their offer was blunt: cash in exchange for access to the company’s IP.
It was a stark reminder that insider threats don’t always unfold in obvious ways. They can surface through unexpected channels, often blending technical vulnerabilities with human factors. And they’re one of the more prevalent forms of security incident that Acumenis sees hitting Australian organisations.
Addressing these risks effectively requires a holistic approach that considers not just security architecture, but culture, awareness, and trust.
In this article, we explore why insider threats can be so difficult to detect, how ISO 27001 provides a framework to address them, and practical steps organisations can take to reduce their exposure.
An insider threat refers to a security risk that originates from within the organisation. This could involve current or former employees, contractors, or suppliers who have – or once had – legitimate access to an organisation’s systems, data, or networks. Unlike external attackers, insiders can exploit their trusted status to bypass traditional security measures, making their actions harder to detect and prevent.
Insider threats can be:
Insider threats are particularly dangerous because they often blend in with normal activity, evade traditional detection tools, and are masked by trust and familiarity within the organisation.
A compromised employee might exfiltrate data slowly over time. A well-meaning staff member might unknowingly introduce risk by using unauthorised tools or sharing sensitive information. And in many cases, the warning signs – if they exist at all – are behavioural rather than technical.
To address the complexity of insider risks, organisations need more than just monitoring tools; they need a structured, risk-based approach.
For organisations that are aligned with ISO 27001, the standard provides exactly that: a comprehensive framework for identifying, prioritising, and mitigating risks such as insider threats through a combination of governance, technical controls, and cultural awareness.
ISO 27001 defines a risk-based approach to information security.
At the heart of the standard is the requirement to conduct a comprehensive risk assessment that identifies threats, vulnerabilities, and potential impacts to the organisation’s information assets. This includes evaluating the risk of insider threat - whether from employees, contractors, or third parties with legitimate access to systems and data.
By performing this assessment, organisations can identify specific types of insider threats that need to be addressed. As food for thought, some of the insider threats Acumenis have recently seen include:
Once risks are identified, ISO 27001 provides a catalogue of controls in Annex A, which can be layered as necessary to mitigate the risks effectively. The following are the most relevant controls from the 2022 revision that support insider threat management:
By aligning your insider threat management strategy with ISO 27001, you can:
Whether you're just beginning your ISO 27001 journey or refining an existing ISMS, focusing on these controls will significantly strengthen your organisation’s resilience against insider threats.
If you would like assistance with addressing insider risk or implementing ISO 27001, we'd love to chat. We support organisations Australia wide, with specialists in Brisbane and Toowoomba.
Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.
